IT Security Gateway for Legacy Control Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial technological systems face challenges in maintaining IT security due to obsolete automated control systems, lack of regular updates, and inadequate security measures, leading to vulnerabilities from malicious actions and unintentional mistakes, which can disrupt processes and introduce errors.

Innovation Solution

A method and system for stepwise increasing IT security by intercepting traffic between elements, identifying vulnerable components, analyzing their severity, and operating the most vulnerable parts in a protected environment using a hypervisor mode to ensure secure data exchange and control, while maintaining system functionality.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If obsolete automated control systems are used in technological systems, then system compatibility and operational stability are maintained, but IT security and protection against malicious actions deteriorate

Engineering Contradiction:
Improveoperational stabilityVSAvoidIT security vulnerabilities
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

A security gateway is introduced as an intermediary component between the obsolete automated control system and the external network. The gateway intercepts all communications, analyzes them for security threats, and filters malicious actions while allowing legitimate operations to pass through, thus protecting the legacy system without disrupting its operational stability

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The technological system is segmented into isolated zones with different security levels. The obsolete control system operates in a restricted zone separated from the external network by security gateways, allowing the system to maintain its legacy functionality while being protected from external threats through architectural isolation

Inventive Principle:
Principle #1Segmentation

2Object-affected harmful factors

If frequent updates of control systems are performed to improve security, then IT security is improved, but system interruptions and operational disruptions increase

Engineering Contradiction:
ImproveIT securityVSAvoidcontinuous operation
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

Security updates and patches are applied in advance to the security gateway and protective software components before they are needed to counter actual attacks. This allows the system to maintain security improvements without interrupting the operational processes, as the protective measures are pre-installed and ready

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If existing obsolete automated control systems are connected to computer networks to enable data exchange, then system connectivity and data sharing are improved, but security against external malicious actions deteriorates

Engineering Contradiction:
Improvenetwork connectivityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

Security gateways serve as intermediary components that enable network connectivity for obsolete control systems while filtering out malicious actions. The gateways allow legitimate data exchange and communication with external networks while blocking security threats, thus achieving both connectivity and security

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security protection functions are extracted from the obsolete control system itself and placed in separate security gateway components. This allows the legacy system to maintain its original simplicity and functionality while security concerns are handled by dedicated protective infrastructure

Inventive Principle:
Principle #2Taking out (Extraction)

4Object-affected harmful factors

If comprehensive security measures are implemented in existing control systems, then protection level is improved, but system complexity and resource requirements increase

Engineering Contradiction:
Improveprotection levelVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

Complex security functions are extracted from the obsolete control system and implemented in separate security gateway components. This allows comprehensive security protection to be added without increasing the complexity of the original control system, as the security logic is isolated in dedicated hardware or software modules

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP3716109B1System and method of stepwise increasing the it security of elements of a technological system
Publication Date: 2022.09.28 AO KASPERSKY LAB
  • EP3716109B1 patent drawingFigure 1a
  • EP3716109B1 patent drawingFigure 1b
  • EP3716109B1 patent drawingFigure 2

AI summary

The present disclosure provides systems and methods to stepwise increasing the IT security of elements of a technological system. In one example, the method comprises gathering data on technological systems and a plurality of elements comprising the technological system by intercepting traffic between the plurality of elements using data exchange protocols, identifying vulnerable elements of the technological system by one or more of: detecting suspicious actions on the vulnerable elements and statistical data relating to the elements, analyzing the vulnerable elements to generate a classification of severity of vulnerabilities of the vulnerable elements, identifying most vulnerable portions of the vulnerable elements as compared to other elements in the vulnerable elements, operating the most vulnerable portions of the vulnerable elements in a protected environment.